Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

NFTs worth $1.7M stolen via OpenSea phishing attack

Last updated

Collectors of NFTs that used OpenSea have been affected by a phishing attack, with a total of 254 tokens estimated to be worth more than $1.7 million stolen over a three-hour period.

On Saturday, OpenSea became aware of rumors about smart contracts connected to the non-fungible token (NFT) marketplace. In investigating the claims, it discovered that users were actually being affected by a fairly typical phishing attack.

Emails set to look like an OpenSea Community Update were sent to customers, inviting them to migrate their Etherium listings to a new smart contract. As OpenSea introduced its own legitimate smart contract one day prior, the phishing email took advantage of the change.

According to OpenSea and CEO Devin Finzer on Twitter, the phishing attack doesn't appear to be connected to the OpenSea website itself, and was operated separately, reports Decrypt. It seems that only 32 people were affected by the email, signing a contract with a malicious payload, which led to the victims signing over NFTs to the attacker.

In an explainer thread linked by Finzer, it appears the attack had the victims signing half of a Wyvern order, referencing an open-source standard typically used in NFT smart contracts. The order was effectively empty except for call data and a target of the attacker's contract, with the victim signing half while the attacker signed the other.

After signing, the attacker calls their own contract listed in the double-signed order, which then starts the process of transferring the victim's NFTs to the attacker.

Since the discovery, some of the NFTs that were taken have been returned, while others have been sold by the attacker. An examination of the attacker's wallet reveals it has collected Etherium valued at $1.7 million, far below a $200 million valuation that spread via rumors.

OpenSea is still investigating the incident to determine how exactly the attack took place.



18 Comments

bonobob 13 Years · 395 comments

 smart contracts connected to the non-fungible token (NFT) marketplace. 

Read on AppleInsider

Did you mean to say non-functional tokens?  The only thing I've seen them accomplish is to transfer wealth from one person to another, with no value in return.

badmonk 11 Years · 1336 comments

Looks like people got suckered twice.

M68000 7 Years · 887 comments

Time will tell with all this bitcoin and crypto stuff.  Some believe it is really just a big Ponzi scheme.  Warren Buffett has said he has no interest - he said it produces nothing therefore it has no value.  

viclauyyc 10 Years · 847 comments

M68000 said:
Time will tell with all this bitcoin and crypto stuff.  Some believe it is really just a big Ponzi scheme.  Warren Buffett has said he has no interest - he said it produces nothing therefore it has no value.  

This also applies to some currencies in the world which is no longer back by gold or silver. But of course, these currencies is back by the countries. So people trust these money based on the faith of the country can guarantee the value. Will a country back a crypto currency, I don’t think so, risk too high and almost no way to control it. But will a country used it their own currencies, it is already happening.